Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

2025 will be a ‘pivotal year’ for Meta’s augmented and virtual reality, says CTO

June 6, 2025

Why investing in growth-stage AI startups is getting riskier and more complicated

June 6, 2025

Anthropic appoints a national security expert to its governing trust

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » North Korean hackers set up 3 shell companies to scam crypto devs
Blockchain

North Korean hackers set up 3 shell companies to scam crypto devs

HarishBy HarishApril 25, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


A subgroup of the North Korea-linked hacker organization Lazarus set up three shell companies, two in the United States, to deliver malware to unsuspecting users.

The three sham crypto consulting firms — BlockNovas, Angeloper Agency and SoftGlide — are being used by the North Korean hacker group Contagious Interview to distribute malware through fake job interviews, Silent Push threat analysts said in an April 24 report.

Silent Push senior threat analyst Zach Edwards said in an April 24 statement to X that two shell companies are registered as legitimate businesses in the US.

“These websites and a huge network of accounts on hiring / recruiting websites are being used to trick people into applying for jobs,” he said.

“During the job application process an error message is displayed as someone tries to record an introduction video. The solution is an easy click fix copy and paste trick, which leads to malware if the unsuspecting developer completes the process.”

During the sham job interview, an error message is displayed, requiring the user to click, copy, and paste to fix it, which leads to the malware infection. Source: Zach Edwards

Three strains of malware — BeaverTail, InvisibleFerret and Otter Cookie — are being used according to Silent Push.

BeaverTail is malware primarily designed for information theft and to load further stages of malware. OtterCookie and InvisibleFerret mainly target sensitive information, including crypto wallet keys and clipboard data.

Silent Push analysts said in the report that hackers use GitHub job listing’s and freelancer websites to look for victims, among others.

AI used to create fake employees 

The ruse also involves the hackers using AI-generated images to create profiles of employees for the three front crypto companies and stealing images of real people.

“There are numerous fake employees and stolen images from real people being used across this network. We’ve documented some of the obvious fakes and stolen images, but it’s very important to appreciate that the impersonation efforts from this campaign are different,” Edwards said.

“In one of the examples, the threat actors took a real photo from a real person, and then appeared to have run it through an AI image modifier tool to create a subtly different version of that same image.”

Related: Fake Zoom malware steals crypto while it’s ‘stuck’ loading, user warns

This malware campaign has been ongoing since 2024. Edwards says there are known public victims.

Silent Push identified two developers targeted by the campaign; one of them reportedly had their MetaMask wallet compromised.

The FBI has since shut down at least one of the companies.

“The Federal Bureau of Investigation (FBI) acquired the Blocknovas domain, but Softglide is still live, along with some of their other infrastructure,” Edwards said.

Cryptocurrencies, Hackers, North Korea, Cybersecurity
Source: Zach Edwards

At least three crypto founders have reported in March that they foiled an attempt from alleged North Korean hackers to steal sensitive data through fake Zoom calls.

Groups such as the Lazarus Group are the prime suspects in some of the biggest cyber thefts in Web3, including the Bybit $1.4 billion hack and the $600 million Ronin network hack.

Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleEthereum devs test a 4x increase in gas limit for Fusaka hard fork
Next Article Sebastián Lelio, Lukas Dhont and Jasmila Zbanić Pitching at Cannes
Harish
  • Website
  • X (Twitter)

Related Posts

Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

June 6, 2025

How to Earn Passive Income with Peer-to-Peer Lending

June 6, 2025

Mass data deletion by governments is accelerating.

June 6, 2025

Cointelegraph Bitcoin & Ethereum Blockchain News

June 6, 2025

Moonbirds NFT Sales Jump 2,525% After Orange Cap Games Acquires IP

June 6, 2025

Saylor’s Strategy upsized stock offering to $1B for Bitcoin purchases

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

2025 will be a ‘pivotal year’ for Meta’s augmented and virtual reality, says CTO

June 6, 2025

Why investing in growth-stage AI startups is getting riskier and more complicated

June 6, 2025

Anthropic appoints a national security expert to its governing trust

June 6, 2025

Jordan Moldo Joins A/Vantage Pictures as Executive VP

June 6, 2025
Don't Miss
Blockchain

Bitcoin market of 2025 driven by stablecoin regulation: Finance Redefined

June 6, 20256 Mins Read

Despite a week of price consolidation for Bitcoin (BTC), emerging digital asset legislation may provide…

How to Earn Passive Income with Peer-to-Peer Lending

June 6, 2025

Mass data deletion by governments is accelerating.

June 6, 2025

Cointelegraph Bitcoin & Ethereum Blockchain News

June 6, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

2025 will be a ‘pivotal year’ for Meta’s augmented and virtual reality, says CTO

June 6, 2025

Why investing in growth-stage AI startups is getting riskier and more complicated

June 6, 2025

Anthropic appoints a national security expert to its governing trust

June 6, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.